3dflipbook develops a specialized web-based document-visualization product focused on interactive page-flip presentations, where its vulnerability disclosures center on cross-site scripting weaknesses in page rendering and user input handling. The narrow product scope and application-layer attack surface characterize this vendor's profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 3dflipbook over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4453MEDIUM The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a | Jan 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-0423MEDIUM The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any aut | Mar 21, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-43152MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery a | Aug 12, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-1081MEDIUM The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1 | Feb 21, 2024 | 5.4 | 18 | NO | NO |
CVE-2025-5289MEDIUM The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters | Jun 21, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-3883MEDIUM The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input | May 2, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-6776MEDIUM The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient in | Jan 11, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 3dflipbook.
Media articles that mention a CVE ID that affects a product developed by 3dflipbook — matched by CVE ID, not by vendor name.